CVEs we hold for Woocommerce
Records whose assigning authority named Woocommerce as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9284WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information…WooCommerce PayPal Payments
CVE-2026-57329WordPress WooCommerce Designer Pro plugin <= 1.9.34 - Cross Site Scripting (XSS) vulnerabilityWooCommerce Designer Pro
CVE-2026-2381WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via…WooCommerce Stripe Payment Gateway
CVE-2026-18391WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object InjectionUnknown WooCommerce Subscriptions
CVE-2026-1710WooPayments <= 10.5.1 - Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajaxWooCommerce Payments
CVE-2026-14853WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing AuthorizationUnknown WooCommerce Bookings
CVE-2025-14073WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information DisclosureWooCommerce PayPal Payments
CVE-2025-13457WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in…WooCommerce Square
CVE-2024-3983WooCommerce Customers Manager < 30.1 - Bulk Action via CSRFUnknown WooCommerce Customers Manager
CVE-2024-37297WooCommerce has a Cross-Site Scripting Vulnerability in checkout & registration formswoocommerce
CVE-2024-32517WordPress Custom Thank You Page Customize For WooCommerce by Binary Carpenter plugin <= 1.4.12 - Broken Access Control…WooCommerce by Binary Carpenter
CVE-2024-2843WooCommerce Customers Manager < 30.1 - User Deletion via CSRFUnknown WooCommerce Customers Manager
CVE-2024-24799WordPress WooCommerce Box Office plugin <= 1.2.2 - Broken Access Control vulnerabilityWooCommerce Box Office
CVE-2024-2322WooCommerce Cart Abandonment Recovery < 1.2.27 - Templates/Abandoned Orders Deletion via CSRFUnknown WooCommerce Cart Abandonment Recovery
CVE-2024-1756WooCommerce Customers Manager < 29.8 - Subscriber+ Email DisclosureUnknown WooCommerce Customers Manager
CVE-2024-1747WooCommerce Customers Manager < 30.2 - Subscriber+ Stored XSSUnknown WooCommerce Customers Manager
CVE-2024-1743WooCommerce Customers Manager < 29.8 - Reflected XSSUnknown WooCommerce Customers Manager
CVE-2024-10820WooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File UploadUnknown WooCommerce Upload Files
CVE-2024-10563WooCommerce Cart Count Shortcode < 1.1.0 - Contributor+ XSSUnknown WooCommerce Cart Count Shortcode
CVE-2024-10486Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info FileWooCommerce
CVE-2024-0399WooCommerce Customers Manager < 29.7 - Subscriber+ SQL InjectionUnknown WooCommerce Customers Manager
CVE-2023-5601WooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File UploadUnknown WooCommerce Ninja Forms Product Add-ons
CVE-2023-5325Woocommerce Vietnam Checkout < 2.0.6 - Unauthenticated Stored XSSUnknown Woocommerce Vietnam Checkout
CVE-2023-51502WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR)WooCommerce Stripe Payment Gateway
CVE-2023-51499WordPress WooCommerce Shipping Per Product plugin <= 2.5.4 - Broken Access Control vulnerabilityWooCommerce Shipping Per Product
CVE-2023-47789WordPress WooCommerce Canada Post Shipping Plugin <= 2.8.3 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Canada Post Shipping Method
CVE-2023-47787WordPress WooCommerce Bookings Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Bookings
CVE-2023-44999WordPress WooCommerce Stripe Gateway plugin <= 7.6.0 - Cross Site Request Forgery (CSRF) vulnerabilityWooCommerce Stripe Payment Gateway
CVE-2023-37873WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Scripting (XSS)WooCommerce Shipping Multiple Addresses
CVE-2023-37871WordPress WooCommerce GoCardless Gateway Plugin <= 2.5.6 is vulnerable to Insecure Direct Object References (IDOR)WooCommerce GoCardless
CVE-2023-36514WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Shipping Multiple Addresses
CVE-2023-36513WordPress AutomateWoo Plugin <= 5.7.5 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce AutomateWoo
CVE-2023-36511WordPress WooCommerce Order Barcodes Plugin <= 1.6.4 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Order Barcodes
CVE-2023-35918WordPress WooCommerce Bulk Stock Management Plugin <= 2.2.33 is vulnerable to Cross Site Scripting (XSS)WooCommerce Bulk Stock Management
CVE-2023-35917WordPress WooCommerce PayPal Payments Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce PayPal Payments
CVE-2023-35914WordPress WooCommerce Subscriptions Plugin <= 5.1.2 is vulnerable to Insecure Direct Object References (IDOR)WooCommerce Woo Subscriptions
CVE-2023-35881WordPress WooCommerce One Page Checkout plugin <= 2.3.0 - Local File Inclusion vulnerabilityWooCommerce One Page Checkout
CVE-2023-35880WordPress WooCommerce Brands Plugin <= 1.6.49 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Brands
CVE-2023-35879WordPress WooCommerce Product Vendors Plugin <= 2.1.78 is vulnerable to SQL InjectionWooCommerce Product Vendors
CVE-2023-35876WordPress WooCommerce Square Plugin <= 3.8.1 is vulnerable to Insecure Direct Object References (IDOR)WooCommerce Square
CVE-2023-3508WooCommerce Pre-Orders < 2.0.3 - Unauthorised Actions via CSRFUnknown WooCommerce Pre-Orders
CVE-2023-3507WooCommerce Pre-Orders < 2.0.3 - Arbitrary Pre-Order Canceling via CSRFUnknown WooCommerce Pre-Orders
CVE-2023-35049WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerabilityWooCommerce Stripe Payment Gateway
CVE-2023-34004WordPress WooCommerce Box Office Plugin <= 1.1.50 is vulnerable to Cross Site Scripting (XSS)WooCommerce Box Office
CVE-2023-34000WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.4.0 is vulnerable to Insecure Direct Object References (IDOR)WooCommerce Stripe Payment Gateway
CVE-2023-33332WordPress WooCommerce Product Vendors Plugin <= 2.1.76 is vulnerable to Cross Site Scripting (XSS)WooCommerce Product Vendors
CVE-2023-33331WordPress WooCommerce Product Vendors Plugin <= 2.1.76 is vulnerable to SQL InjectionWooCommerce Product Vendors
CVE-2023-33330WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.50 is vulnerable to SQL InjectionWooCommerce AutomateWoo
CVE-2023-33319WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Cross Site Scripting (XSS)WooCommerce Follow-Up Emails (AutomateWoo)
CVE-2023-33318WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Arbitrary File UploadWooCommerce AutomateWoo
CVE-2023-33317WordPress WooCommerce Warranty Requests Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)WooCommerce Returns and Warranty Requests
CVE-2023-33316WordPress WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Follow-Up Emails (AutomateWoo)
CVE-2023-32802WordPress WooCommerce Pre-Orders Plugin <= 1.9.0 is vulnerable to Cross Site Scripting (XSS)WooCommerce Pre-Orders
CVE-2023-32801WordPress WooCommerce Composite Products Plugin <= 8.7.5 is vulnerable to Cross Site Scripting (XSS)WooCommerce Composite Products
CVE-2023-32799WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.3 is vulnerable to Insecure Direct Object References…WooCommerce Shipping Multiple Addresses
CVE-2023-32795WordPress WooCommerce Product Add-ons Plugin <= 6.1.3 is vulnerable to PHP Object InjectionWooCommerce Product Add-Ons
CVE-2023-32794WordPress WooCommerce Product Add-ons Plugin <= 6.1.3 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Product Add-Ons
CVE-2023-32793WordPress WooCommerce Pre-Orders Plugin <= 2.0.0 is vulnerable to Cross Site Scripting (XSS)WooCommerce Pre-Orders
CVE-2023-32747WordPress WooCommerce Bookings Plugin <= 1.15.78 is vulnerable to Insecure Direct Object References (IDOR)WooCommerce Bookings
CVE-2023-32746WordPress WooCommerce Brands Plugin <= 1.6.45 is vulnerable to Cross Site Scripting (XSS)WooCommerce Brands
CVE-2023-32745WordPress AutomateWoo Plugin <= 5.7.1 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce AutomateWoo
CVE-2023-32744WordPress WooCommerce Product Recommendations Plugin < 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)WooCommerce Product Recommendations
CVE-2023-32743WordPress AutomateWoo Plugin <= 5.7.1 is vulnerable to SQL InjectionWooCommerce AutomateWoo
CVE-2023-2329WooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRFUnknown WooCommerce Google Sheet Connector
CVE-2023-2179WooCommerce Order Status Change Notifier <= 1.1.0 - Subscriber+ Arbitrary Order Status UpdateUnknown WooCommerce Order Status Change Notifier
CVE-2023-0865WooCommerce Multiple Customer Addresses & Shipping < 21.7 - Arbitrary Address Creation/Deletion/Access/Update via IDORUnknown WooCommerce Multiple Customer Addresses & Shipping
CVE-2022-50972WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.phpWooCommerce
CVE-2022-4328WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File UploadUnknown WooCommerce Checkout Field Manager
CVE-2022-4000WooCommerce Shipping - DPD baltic < 1.2.11 - Admin+ Stored XSSUnknown WooCommerce Shipping
CVE-2022-2537WooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site ScriptingUnknown WooCommerce PDF Invoices & Packing Slips
CVE-2022-2092WooCommerce PDF Invoices & Packing Slips < 2.16.0 - Reflected Cross-Site ScriptingUnknown WooCommerce PDF Invoices & Packing Slips
CVE-2022-1673WooCommerce Green Wallet Gateway < 1.0.2 - Reflected Cross Site Scripting in checkout pageUnknown WooCommerce Green Wallet Gateway
CVE-2022-1546WooCommerce - Product Importer <= 1.5.2 - Reflected Cross-Site ScriptingUnknown WooCommerce – Product Importer
CVE-2022-0818Coupon Affiliates < 4.16.4.5 - Unauthenticated Stored XSSUnknown WooCommerce Affiliate Plugin – Coupon Affiliates
CVE-2022-0149WooCommerce – Store Exporter < 2.7.1 - Reflected Cross-Site Scripting (XSS)Unknown WooCommerce – Store Exporter
CVE-2021-39308WooCommerce myghpay Payment Gateway <= 3.0 Reflected Cross-Site ScriptingWooCommerce myghpay Payment Gateway
CVE-2021-38341WooCommerce Payment Gateway Per Category <= 2.0.10 Reflected Cross-Site ScriptingWooCommerce Payment Gateway Per Category
CVE-2021-32790Blind SQL Injection possible via Authenticated Web-hook Search API Endpointwoocommerce
CVE-2021-32789Arbitrary SQL (SQL injection) possible via the Store API component.woocommerce-gutenberg-products-block
CVE-2021-24991WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site ScriptingUnknown WooCommerce PDF Invoices & Packing Slips
CVE-2021-24212WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCEUnknown WooCommerce Help Scout
CVE-2021-24171WooCommerce Upload Files < 59.4 - Unauthenticated Arbitrary File UploadUnknown WooCommerce Upload Files
CVE-2020-36841WooCommerce Smart Coupons <= 4.6.0 - Unauthenticated Coupon CreationWooCommerce Smart Coupons
CVE-2018-25325Woocommerce CSV Importer 3.3.6 Path Traversal File Deletionwoocommerce-csvimport WooCommerce CSV-Importer
91 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.